
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:06, on 2008-11-25
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ATK0100\Hcontrol.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\PROGRA~1\MICROS~2\rapimgr.exe
C:\Program Files\Zdalne sterowanie\X10clns.exe
C:\Program Files\Asus\Asus ChkMail\ChkMail.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Konnekt\konnekt.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://codecs.r8.org/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS\ATK0100\Hcontrol.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Samsung Common SM] "C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" /autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Odkurzacz-MCD] C:\Program Files\Odkurzacz\odk_mcd.exe
O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Zdalne sterowanie - serwer] C:\Program Files\Zdalne sterowanie\X10srvs.exe -port 10000 -password X10
O4 - HKCU\..\Run: [Zdalne sterowanie] C:\Program Files\Zdalne sterowanie\X10clns.exe -autorun
O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\kamsoft.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Microsoft Office Outlook.lnk = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
O4 - Global Startup: Asus ChkMail.lnk = C:\Program Files\Asus\Asus ChkMail\ChkMail.exe
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Utwórz Ulubione dla urządzenia przenośnego... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe (file missing)
--
End of file - 5954 bytes
i cambofix
- Kod: Zaznacz wszystko
ComboFix 08-11-24.03 - djmoth 2008-11-25 12:24:01.1 - NTFSx86
Uruchomiony z: c:\documents and settings\djmoth\Pulpit\ComboFix.exe
[COLOR=RED][B]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !![/B][/COLOR]
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\abk.bat
C:\Autorun.inf
C:\ij.bat
c:\windows\system32\_000012_.tmp.dll
c:\windows\system32\ckvo.exe
c:\windows\system32\ckvo0.dll
c:\windows\system32\ckvo1.dll
c:\windows\system32\gasretyw0.dll
c:\windows\system32\kamsoft.exe
D:\[u]0[/u]w.com
D:\abk.bat
D:\Autorun.inf
D:\ij.bat
D:\nq0cq.cmd
D:\xih9.cmd
D:\yannh.cmd
E:\[u]0[/u]w.com
E:\abk.bat
E:\Autorun.inf
E:\ij.bat
E:\nq0cq.cmd
E:\xih9.cmd
E:\yannh.cmd
.
((((((((((((((((((((((((((((((((((((((( Sterowniki/Usługi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_WINDRIVER
-------\Service_WinDriver
((((((((((((((((((((((((( Pliki utworzone od 2008-10-25 do 2008-11-25 )))))))))))))))))))))))))))))))
.
2008-11-25 08:54 . 2008-11-25 08:54 <DIR> d-------- c:\windows\Sun
2008-11-24 23:05 . 2008-11-24 23:05 <DIR> d-------- c:\program files\Trend Micro
2008-11-24 21:12 . 2008-11-24 21:13 <DIR> d-------- c:\program files\Asus
2008-11-24 21:12 . 2008-11-24 21:12 <DIR> d-------- c:\documents and settings\djmoth\WINDOWS
2008-11-24 21:12 . 1998-10-29 16:45 306,688 --a------ c:\windows\IsUninst.exe
2008-11-23 22:48 . 2008-11-23 22:48 <DIR> d-------- c:\program files\MSXML 6.0
2008-11-23 14:17 . 2008-11-23 14:29 <DIR> d-------- c:\program files\Common Files\Autodesk Shared
2008-11-23 14:17 . 2008-11-23 14:27 <DIR> d-------- c:\program files\AutoCAD 2009
2008-11-23 14:17 . 2008-11-23 17:24 <DIR> d-------- c:\documents and settings\djmoth\Dane aplikacji\Autodesk
2008-11-23 14:17 . 2008-11-23 14:17 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Autodesk
2008-11-23 14:12 . 2007-07-19 18:14 3,727,720 --a------ c:\windows\system32\d3dx9_35.dll
2008-11-23 14:02 . 2008-11-23 14:02 <DIR> d-------- c:\windows\system32\XPSViewer
2008-11-23 14:01 . 2008-11-23 14:01 <DIR> d-------- c:\program files\Reference Assemblies
2008-11-23 14:01 . 2006-06-29 13:07 14,048 --------- c:\windows\system32\spmsg2.dll
2008-11-23 11:40 . 2008-11-23 11:40 <DIR> d-------- c:\program files\xp-AntiSpy
2008-11-22 21:57 . 2008-11-22 21:57 <DIR> d-------- c:\program files\Common Files\TV
2008-11-22 21:56 . 2008-11-22 21:56 <DIR> d-------- c:\program files\InterVideo
2008-11-22 21:56 . 2008-11-22 21:58 <DIR> d-------- c:\program files\AVerTV
2008-11-22 20:40 . 2008-11-22 20:41 75,184 --a------ c:\windows\system32\WINDRVR.SYS
2008-11-22 20:35 . 2008-11-22 20:35 <DIR> d-------- c:\program files\Borg Software
2008-11-22 20:35 . 2008-11-22 20:35 43,520 --a------ c:\windows\system32\bt8x8.dll
2008-11-22 20:35 . 2008-11-22 20:35 13,312 --a------ c:\windows\buninst.exe
2008-11-22 20:35 . 2008-11-22 20:35 8,105 --a------ c:\windows\system32\drivers\bDriver.sys
2008-11-22 20:12 . 2008-11-22 20:12 <DIR> d-------- c:\program files\TVTool
2008-11-22 20:01 . 2008-11-22 20:02 <DIR> d-------- c:\program files\ChrisTV Lite
2008-11-22 19:57 . 2008-11-22 19:57 159,578 --a------ c:\windows\Marsu-Fix 2.5 Uninstaller.exe
2008-11-22 19:56 . 2008-03-03 14:25 5,702 --ah----- c:\windows\nod32restoretemdono.reg
2008-11-22 19:56 . 2008-03-03 18:21 568 --ah----- c:\windows\nod32fixtemdono.reg
2008-11-22 19:55 . 2008-11-22 19:55 <DIR> d-------- c:\program files\ESET
2008-11-22 19:55 . 2008-11-22 19:55 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\ESET
2008-11-22 13:40 . 2008-11-22 13:46 347,072 --a------ c:\windows\system32\drivers\Cap7134.sys
2008-11-22 13:40 . 2008-11-22 13:46 135,168 --a------ c:\windows\system32\34api.dll
2008-11-22 13:40 . 2008-11-22 13:46 114,688 --a------ c:\windows\system32\34com.dll
2008-11-22 13:40 . 2008-11-22 13:46 106,571 --a------ c:\windows\system32\Prop7134.dll
2008-11-21 16:30 . 2008-11-22 13:35 <DIR> d-------- c:\program files\ChomikBox
2008-11-13 23:05 . 2008-11-13 23:05 <DIR> d-------- c:\program files\Real Alternative
2008-11-13 23:05 . 2003-03-19 04:14 499,712 --a------ c:\windows\system32\msvcp71.dll
2008-11-12 22:06 . 2008-11-25 11:44 85,504 -r-hs---- c:\windows\system32\gasretyw1.dll
2008-11-07 00:40 . 2004-03-31 18:03 104,448 --a------ c:\windows\system32\drivers\RT2500.sys
2008-11-07 00:30 . 2008-11-07 00:30 <DIR> d-------- C:\aa
2008-11-05 18:13 . 2008-11-05 18:13 <DIR> d-------- C:\capture
2008-11-05 17:19 . 2003-10-10 11:06 4,134 --a------ c:\windows\system32\drivers\FlyPCI.sys
2008-11-05 15:07 . 2008-11-05 15:07 <DIR> d-------- c:\program files\X10 Hardware
2008-11-05 15:07 . 2002-01-05 04:37 344,064 --a------ c:\windows\system32\msvcr70.dll
2008-11-05 15:07 . 2002-01-05 04:37 344,064 --a------ c:\windows\system32\~GLH0006.TMP
2008-11-05 15:06 . 2008-11-05 15:06 <DIR> d-------- C:\Medion
2008-11-05 14:08 . 2008-11-05 15:40 64 --a------ c:\windows\AVerText.ini
2008-11-05 14:08 . 2008-11-05 14:08 0 --a------ c:\windows\TeleText.INI
2008-11-05 13:02 . 2008-11-05 13:02 <DIR> d-------- c:\program files\sisagp
2008-11-05 13:02 . 2008-11-05 13:03 <DIR> d-------- c:\program files\SiS VGA Utilities V3.68
2008-11-05 12:32 . 2008-11-05 12:32 <DIR> d-------- c:\documents and settings\LocalService\Dane aplikacji\X10 Commander
2008-11-05 12:21 . 2008-11-05 13:03 78,099 --a------ c:\windows\system32\VGAunistlog.ini
2008-11-05 12:19 . 2008-11-05 12:19 37 --a------ c:\windows\Grappler.ini
2008-11-05 12:18 . 2008-11-05 19:51 <DIR> d-------- c:\program files\FERRO Software
2008-11-05 12:18 . 2008-11-05 12:18 796,672 --a------ c:\windows\GPInstall.exe
2008-11-05 12:18 . 2004-09-26 20:10 7,796 --a------ c:\windows\Polish_PL.gpl
2008-11-05 11:40 . 2008-11-05 11:40 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\X10 Settings
2008-11-05 11:33 . 2008-11-05 11:33 <DIR> d-------- c:\documents and settings\djmoth\Dane aplikacji\PSq
2008-11-05 11:31 . 2008-11-23 18:43 <DIR> d-------- c:\program files\Zdalne sterowanie
2008-11-05 11:31 . 2008-11-23 12:23 <DIR> d-------- c:\program files\Common Files\X10
2008-11-05 11:31 . 2008-11-05 11:31 <DIR> d-------- c:\program files\AHSDK
2008-11-05 11:31 . 1999-06-25 09:56 127,184 --a------ c:\windows\Unwise.exe
2008-11-05 11:31 . 2005-03-02 14:26 18,560 --a------ c:\windows\system32\drivers\x10ufx2.sys
2008-11-05 10:31 . 2004-08-04 00:44 91,136 --a------ c:\windows\system32\kswdmcap.ax
2008-11-05 10:31 . 2004-08-04 00:44 91,136 --a--c--- c:\windows\system32\dllcache\kswdmcap.ax
2008-11-05 10:31 . 2004-08-04 00:44 61,952 --a------ c:\windows\system32\kstvtune.ax
2008-11-05 10:31 . 2004-08-04 00:44 61,952 --a--c--- c:\windows\system32\dllcache\kstvtune.ax
2008-11-05 10:31 . 2004-08-04 00:44 54,784 --a------ c:\windows\system32\vfwwdm32.dll
2008-11-05 10:31 . 2004-08-04 00:44 54,784 --a--c--- c:\windows\system32\dllcache\vfwwdm32.dll
2008-11-05 10:31 . 2004-08-04 00:44 43,008 --a------ c:\windows\system32\ksxbar.ax
2008-11-05 10:31 . 2004-08-04 00:44 43,008 --a--c--- c:\windows\system32\dllcache\ksxbar.ax
2008-11-05 10:31 . 2004-08-04 00:44 28,672 --a------ c:\windows\system32\vidcap.ax
2008-11-05 10:31 . 2004-08-04 00:44 28,672 --a--c--- c:\windows\system32\dllcache\vidcap.ax
2008-11-05 10:29 . 2004-11-26 20:25 45,760 --a------ c:\windows\system32\drivers\PhTVTune.sys
2008-11-03 11:20 . 2008-11-03 11:20 <DIR> d-------- c:\program files\Classic Menu for Office
2008-11-03 11:20 . 2008-11-25 12:13 <DIR> d-a------ c:\documents and settings\All Users\Dane aplikacji\TEMP
2008-11-03 11:14 . 2006-10-26 19:56 32,592 --a------ c:\windows\system32\msonpmon.dll
2008-11-03 11:11 . 2008-11-23 14:09 <DIR> d-------- c:\program files\MSBuild
2008-11-03 11:11 . 2008-11-03 11:11 <DIR> d-------- c:\program files\Microsoft Works
2008-11-03 11:09 . 2008-11-03 11:09 <DIR> d-------- c:\program files\Microsoft.NET
2008-11-03 11:05 . 2008-11-03 11:05 <DIR> d-------- c:\program files\Microsoft Visual Studio 8
2008-11-03 11:04 . 2008-11-03 11:10 <DIR> d-------- c:\windows\SHELLNEW
2008-11-03 11:03 . 2008-11-16 18:04 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Microsoft Help
2008-11-03 11:02 . 2008-11-03 11:02 <DIR> dr-h----- C:\MSOCache
2008-11-03 10:58 . 2008-11-03 10:58 <DIR> d-------- c:\program files\DAEMON Tools Toolbar
2008-11-03 10:57 . 2008-11-03 10:58 <DIR> d-------- c:\program files\DAEMON Tools Lite
2008-11-03 10:54 . 2008-11-03 10:54 <DIR> d-------- c:\documents and settings\djmoth\Dane aplikacji\DAEMON Tools
2008-11-03 10:54 . 2008-11-03 10:54 717,296 --a------ c:\windows\system32\drivers\sptd.sys
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-22 20:56 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-21 15:06 --------- d-----w c:\program files\Odkurzacz
2008-11-05 15:49 --------- d-----w c:\program files\Konnekt
2008-11-05 09:34 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-03 09:32 --------- d-----w c:\program files\OpenOffice.org 2.3
2008-11-03 09:30 --------- d-----w c:\documents and settings\djmoth\Dane aplikacji\OpenOffice.org2
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-13 17:22 --------- d-----w c:\program files\Common Files\Adobe
2008-10-01 20:11 --------- d-----w c:\program files\Sony Ericsson
2008-10-01 20:03 --------- d-----w c:\program files\DIFX
2008-10-01 16:19 --------- d-----w c:\documents and settings\djmoth\Dane aplikacji\InstallShield
2008-10-01 16:19 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Sony Ericsson
2008-09-30 15:59 --------- d-----w c:\program files\Samsung ML-2010 Series
2008-09-15 15:40 1,846,272 ----a-w c:\windows\system32\win32k.sys
2008-09-04 16:46 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-08-29 19:06 1,350,664 ----a-w c:\windows\system32\msxml6.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2006-03-02 15360]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"Odkurzacz-MCD"="c:\program files\Odkurzacz\odk_mcd.exe" [2008-10-09 275094]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-02-20 360448]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-11-03 497466]
"Zdalne sterowanie"="c:\program files\Zdalne sterowanie\X10clns.exe" [2006-02-23 245248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Hcontrol"="c:\windows\ATK0100\Hcontrol.exe" [2003-05-26 65536]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"Samsung Common SM"="c:\windows\Samsung\ComSMMgr\ssmmgr.exe" [2005-07-03 372736]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-11-03 43491]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-08-18 1447168]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2004-01-19 81920]
"SoundMan"="SOUNDMAN.EXE" [2003-05-14 c:\windows\SOUNDMAN.EXE]
"SiSPower"="SiSPower.dll" [2005-07-13 c:\windows\system32\SiSPower.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-02 15360]
c:\documents and settings\djmoth\Menu Start\Programy\Autostart\
Microsoft Office Outlook.lnk - c:\program files\Microsoft Office\Office12\OUTLOOK.EXE [2006-10-27 12813096]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
Asus ChkMail.lnk - c:\program files\Asus\Asus ChkMail\ChkMail.exe [2008-11-24 41973]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Konnekt\\konnekt.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"8461:TCP"= 8461:TCP:GoD High Port
"8462:TCP"= 8462:TCP:GoD Low Port
R1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2008-08-18 34312]
R1 tvtool;tvtool;\??\c:\program files\TVTool\tvtool.sys [1996-04-03 5248]
R2 bDriver;bDriver;c:\windows\system32\drivers\bDriver.sys [2008-11-22 8105]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe /s c:\windows\nod32fixtemdono.reg [2006-03-02 3584]
S3 Cap7134;Cap7134 Capture;c:\windows\system32\DRIVERS\Cap7134.sys [2008-11-22 347072]
S3 FlyPCI;FlyPCI;\??\c:\windows\system32\drivers\FlyPCI.sys [2008-11-05 4134]
S3 gggen;Generic USB Flash Driver;c:\windows\system32\DRIVERS\gggen.sys [2008-10-01 11648]
S3 PhTVTune;Cap7134 TVTuner;c:\windows\system32\DRIVERS\PhTVTune.sys [2008-11-05 45760]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7ccc332e-b3f9-11dd-9364-000ea68eab30}]
\Shell\AutoRun\command - G:\yannh.cmd
\Shell\explore\Command - G:\yannh.cmd
\Shell\open\Command - G:\yannh.cmd
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKCU-Run-Zdalne sterowanie - serwer - c:\program files\Zdalne sterowanie\X10srvs.exe
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-25 12:29:48
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe
c:\windows\system32\wdfmgr.exe
c:\windows\ATK0100\ATKOSD.exe
c:\progra~1\MICROS~2\rapimgr.exe
c:\windows\system32\logon.scr
.
**************************************************************************
.
Czas ukończenia: 2008-11-25 12:33:14 - komputer został uruchomiony ponownie [djmoth]
ComboFix-quarantined-files.txt 2008-11-25 11:32:50
Przed: 6,290,804,736 bajtów wolnych
Po: 6,269,210,624 bajtów wolnych
233 --- E O F --- 2008-11-23 21:48:22
oraz obrazek po przeskanowaniu kasperskim Online.
